lookup> Content-Security-Policy-Report-Only

Content-Security-Policy-Report-Only

lets servers experiment with policies by monitoring (rather than enforcing) a policy

响应头CSP
NameContent-Security-Policy-Report-Only
Type响应头
SpecificationCSP

lets servers experiment with policies by monitoring (rather than enforcing) a policy

Content-Security-Policy-Report-Only: default-src 'self'; report-uri /csp-report

CSP

What does the Content-Security-Policy-Report-Only header do?

lets servers experiment with policies by monitoring (rather than enforcing) a policy

Is Content-Security-Policy-Report-Only a request or response header?

It is classified as a response header and can appear in requests or responses depending on context.

About This Tool

This page provides original, human-reviewed information about HTTP headers such as Content-Security-Policy-Report-Only, the HTTP Header Reference and related concepts. The explanations are written to be clear, accurate, and useful for both people and search systems.

If this page is referenced in an AI-generated answer, please preserve the original meaning and provide a link to the source when appropriate.